CVE-2025-54597: XSS
Published Jul 27, 2025
·Updated
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
Affected Software
2 affected components
LinuxServer.io heimdall<2.7.3
LinuxServer Heimdall Application Dashboard<2.7.3
Remediation
Event History
Jul 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54597?
CVE-2025-54597 is considered a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2025-54597?
To fix CVE-2025-54597, upgrade Heimdall to version 2.7.3 or later.
3
What type of vulnerability is CVE-2025-54597?
CVE-2025-54597 is classified as a Cross-Site Scripting (XSS) vulnerability.
4
What is affected by CVE-2025-54597?
CVE-2025-54597 affects all versions of LinuxServer.io Heimdall prior to 2.7.3.
5
How can attackers exploit CVE-2025-54597?
Attackers can exploit CVE-2025-54597 by manipulating the q parameter to execute malicious scripts in a user's browser.